
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-32711 is a path traversal vulnerability in pydicom, a pure Python package for working with DICOM medical imaging files. It affects versions 2.0.0-rc.1 through 3.0.1 (including all 2.x releases prior to 2.4.5 and 3.x releases prior to 3.0.2), and was disclosed on March 20, 2026. The flaw allows a maliciously crafted DICOMDIR file with a ReferencedFileID set to a path outside the File-set root to enable arbitrary file read, copy, move, or delete operations on the host system. It carries a CVSS v3.1 base score of 7.8 (High) (Github Advisory, pydicom Security Advisory).
The root cause is CWE-22 (Improper Limitation of a Pathname to a Restricted Directory), located in src/pydicom/fileset.py. The vulnerable RecordNode._file_id method converts the ReferencedFileID DICOM attribute directly to a Path object without verifying that the resolved path remains within the File-set root directory — it only checks that the path exists via resolve(strict=True), not that it is contained under the root. As a result, FileSet operations including copy(), write(), and remove()+write(use_existing=True) pass the unchecked path to shutil.copyfile, shutil.move, and Path.unlink, enabling traversal via absolute paths (e.g., /etc/passwd), relative traversal sequences (../...), or symlink-based escapes using syntactically conformant file IDs. The fix in version 3.0.2 adds a containment check using resolved.is_relative_to(root) and raises a PermissionError for out-of-bounds paths (pydicom Security Advisory, Security Fix Commit).
Successful exploitation allows an attacker to read, copy, move, or delete arbitrary files accessible to the process running pydicom, outside the intended File-set root directory. The most realistic server-side scenario involves a user uploading a malicious DICOM File-set archive; when the server loads and re-exports it using FileSet.copy() or FileSet.write(), sensitive server-local files (e.g., /etc/passwd, credentials, configuration files) can be exfiltrated in the exported result. In destructive flows using remove()+write(use_existing=True), files outside the File-set root can be deleted, posing an availability risk. All three CIA pillars are affected: confidentiality (file disclosure), integrity (file modification/move), and availability (file deletion) (pydicom Security Advisory, Github Advisory).
A complete, runnable proof-of-concept Python script is publicly available in the pydicom security advisory, demonstrating the vulnerability by modifying a DICOMDIR file's ReferencedFileID to /etc/passwd and calling FileSet.copy() to extract the file (pydicom Security Advisory). As of the time of reporting, there is no evidence of active in-the-wild exploitation, and no threat actor attribution has been made. The EPSS score is approximately 0.016% (1st percentile), indicating a low current probability of exploitation (Github Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires user interaction — specifically, a user or server process must open a maliciously crafted DICOMDIR file.
DirectoryRecordSequence item so that ReferencedFileID is set to a target path outside the File-set root, such as /etc/passwd or ../../../etc/shadow.FileSet(ds) or FileSet(path_to_dicomdir). pydicom resolves the malicious path and confirms it exists, but does not verify containment within the File-set root.FileSet.copy(output_dir), FileSet.write(), or FileSet.remove()+write(use_existing=True). pydicom passes the unvalidated path to shutil.copyfile, shutil.move, or Path.unlink.copy() flow, the referenced external file (e.g., /etc/passwd) is copied into the exported File-set output directory, where the attacker can retrieve it. In the write() or remove()+write() flow, the file may be moved or deleted from the server (pydicom Security Advisory, Github Advisory)./etc/passwd, configuration files, credential files) appearing in DICOM export or output directories; missing or moved system files in cases of destructive exploitation.FileSet.copy(), FileSet.write(), or FileSet.remove() operations on paths outside the expected DICOM data directory; pydicom warning messages about invalid ReferencedFileID values in DICOMDIR processing logs.ReferencedFileID values with absolute paths (e.g., starting with /) or path traversal sequences (e.g., ../) in the DirectoryRecordSequence./etc/passwd format) from DICOM import/export endpoints (pydicom Security Advisory).The primary remediation is to upgrade pydicom to version 3.0.2 or 2.4.5 (for users on the 2.x branch), both of which include the security fix (pydicom Release v3.0.2, Security Fix Commit). As a workaround prior to patching, restrict acceptance of DICOMDIR files to trusted sources only, and avoid processing untrusted DICOM File-sets with FileSet.copy(), FileSet.write(), or FileSet.remove(). Additionally, implement file integrity monitoring on sensitive directories and run DICOM processing services with least-privilege accounts to limit the impact of exploitation (Github Advisory).
The vulnerability was reported by security researcher jh4nks and published by pydicom maintainer darcymason on March 20, 2026. The fix was merged promptly as a patch release (3.0.2), with the release notes explicitly referencing CVE-2026-32711. OpenSUSE issued security announcements for the affected package, and Fedora also released updates. Tenable published multiple Nessus detection plugins (IDs 303276, 305676, 305672, 310689) for the vulnerability (pydicom Security Advisory, pydicom Release v3.0.2).
Fix availability across major Linux distributions and their releases.
bionic (esm-apps)
pydicom
devel
pydicom
focal (esm-apps)
pydicom
jammy
pydicom
jammy (esm-apps)
pydicom
noble
pydicom
noble (esm-apps)
pydicom
resolute
pydicom
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."